CVE-2020-26977: Medium severity firefox vulnerability
By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. Note: This issue only affects Firefox for Android. Other operating systems are unaffected.. This vulnerability affects Firefox < 84.
Other sources
By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. Note: This issue only affects Firefox for Android. Other operating systems are unaffected.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2020-26977?
CVE-2020-26977 is classified as a medium severity vulnerability affecting Firefox for Android.
How do I fix CVE-2020-26977?
To mitigate CVE-2020-26977, you should upgrade to Mozilla Firefox version 84 or later.
Is CVE-2020-26977 only applicable to certain operating systems?
Yes, CVE-2020-26977 only affects Firefox for Android and does not impact other operating systems.
What happens if an attacker exploits CVE-2020-26977?
Exploiting CVE-2020-26977 could allow an attacker to control the content of a tab while misleading users about the domain displayed in the URL bar.
Which versions of Firefox are affected by CVE-2020-26977?
CVE-2020-26977 affects all versions of Firefox prior to version 84.